Mercy Hospital, Iowa City, Iowa
bd_cb229a485f2d826b · schema v1 · pii pii-v1
Full breach record for Mercy Hospital, Iowa City, Iowa →4 incidents on fileMercy Iowa City (IA) reported to HHS OCR on 2020-11-13 a Hacking/IT Incident affecting 92,795 individuals. An employee was the victim of an email phishing attack exposing ePHI stored in email, including names, addresses, dates of birth, driver's license numbers, Social Security numbers, health insurance information, and treatment information. The CE notified HHS, affected individuals, and media, offered credit monitoring, implemented additional technical safeguards, and retrained staff on phishing awareness. OCR obtained assurances of corrective action.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Nov 13, 2020
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Maine State AGbd_2a28526c953d48e12020-11-13Candidate
- Massachusetts State AGbd_35d6f4ce995941d62020-11-13Verified
- New Hampshire State AGbd_312e904dda8c788e2020-12-01 · +18dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Nov 13 (ME), last Dec 1 (NH) — a 18-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.